{ pkgs, ... }: { networking.nat = { enable = true; enableIPv6 = true; externalInterface = "enp3s0f0"; internalInterfaces = [ "wg0" ]; }; networking.wg-quick.interfaces = { wg0 = { address = [ "172.28.92.1/24" "fd61:754f:ebd3:1c5c::1/64" ]; listenPort = 51820; privateKeyFile = "/var/secrets/wg0.key"; postUp = '' ${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE ${pkgs.iptables}/bin/ip6tables -t nat -A POSTROUTING -o enp3s0f0 -j MASQUERADE ''; preDown = '' ${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE ${pkgs.iptables}/bin/ip6tables -t nat -D POSTROUTING -o enp3s0f0 -j MASQUERADE ''; peers = [ { publicKey = "ZfJaZgG8e2neWJBWcN3cZsDd740Zq+sW/2pmBqSgbRI="; allowedIPs = [ "172.28.92.2" "fd61:754f:ebd3:1c5c::2" ]; } ]; }; }; networking.firewall.allowedUDPPorts = [ 51820 ]; }